Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Ernst & Young has confirmed a data breach linked to a third-party support ticket system that is used by its IT staff. The breach has raised concerns as it could potentially expose sensitive customer information. While the company has begun notifying affected customers, the exact nature of the compromised data has not been detailed. This incident emphasizes the risks associated with relying on third-party services for internal operations, as attackers can exploit vulnerabilities in these systems to gain access to broader networks. Customers are advised to remain vigilant and monitor their accounts for any unusual activity.

Read Original

Thalha Jubair and Owen Flowers, key members of the hacker group known as Scattered Spider, have been sentenced to 66 months in prison in the UK. U.S. authorities previously accused Jubair of being involved in at least 120 cyberattacks, demonstrating a significant level of criminal activity. These attacks are part of a broader trend of cybercrime that affects individuals and organizations alike, raising concerns about online security. The sentencing underscores the legal consequences faced by cybercriminals and serves as a warning to others in the hacking community. As law enforcement continues to crack down on such groups, it highlights the ongoing battle against cyber threats in today's digital landscape.

Read Original
Actively Exploited

Cybercriminals are shifting their focus to 'clean' residential proxies as part of their carding efforts, which involves using stolen credit card information to make unauthorized purchases. Researchers from Flare highlight that these proxies, combined with browser fingerprints and device profiles, help attackers bypass modern fraud detection systems that have become more sophisticated. As residential proxies lose their effectiveness, this trend poses a significant challenge for online retailers and financial institutions, as it allows fraudsters to operate with increased anonymity. This development not only complicates the fight against online fraud but also underscores the need for businesses to enhance their security measures to detect and prevent such tactics. Understanding how these proxies work is crucial for organizations trying to safeguard their systems and customer data.

Read Original

North Korean hackers associated with the Contagious Interview campaign have been using steganography to hide malware in SVG image files. This tactic is part of a broader scheme where fake job postings and coding tests lure victims into downloading malicious code. When users execute these projects, they unknowingly install a multi-stage payload designed to steal browser credentials and cryptocurrency wallets, as well as access files on their systems. This method not only exploits individuals seeking employment but also raises concerns about the effectiveness of cybersecurity measures against such sophisticated attacks. Users need to be vigilant about job offers and coding challenges, especially if they involve downloading files from untrusted sources.

Read Original

The PhantomEnigma campaign has shifted its focus from targeting banking systems in 2025 to exploiting compromised Brazilian government websites in 2026. Attackers are using these .gov.br sites along with authenticated emails to deliver malware. This change in tactics raises concerns about the security of government infrastructures and the potential for widespread malware distribution. The use of official government domains adds a layer of credibility to the malicious communications, making it easier for attackers to deceive users. As this campaign continues to evolve, it poses a significant risk not only to government operations but also to the general public who may interact with these compromised sites.

Read Original

Recent declassified documents reveal that Chinese intelligence has been gathering data on U.S. voters, sparking discussions within the U.S. intelligence community about how to interpret Beijing's actions related to elections. The records provide insight into the methods used by Chinese operatives to collect and analyze voter information, which raises concerns about potential interference in the American electoral process. This situation emphasizes the ongoing risks posed by foreign actors attempting to influence domestic politics. As the U.S. heads into future elections, the implications of these findings could affect public trust in the electoral system and prompt calls for stronger cybersecurity measures to protect voter data.

Read Original
Actively Exploited

A new ransomware strain called Spirals has been linked to a recent attack on an IT services company in South Asia. Cybercriminals quickly gained access to the company's network, executing data theft and encrypting files in less than 24 hours. Spirals, which is written in Rust, employs a unique encryption method by using a separate AES-128 key for each file, making it difficult for victims to recover their data without paying a ransom. This incident highlights the growing sophistication of ransomware attacks and the need for organizations to enhance their cybersecurity measures to protect sensitive information. As ransomware attacks continue to evolve, companies must remain vigilant and prepared for potential threats.

Read Original

Two members of the hacking group Scattered Spider have been sentenced to prison in the UK following their involvement in a significant cyber attack that affected transit systems. This incident, which took place in 2026, saw the hackers compromise critical infrastructure, disrupting services and raising concerns about the security of public transportation systems. The sentencing marks a notable outcome in one of the UK's largest cybercrime cases, reflecting law enforcement's commitment to tackling cyber threats. The attack not only impacted transit operations but also highlighted vulnerabilities in the systems that support essential services. As cyber attacks become more sophisticated, this case serves as a reminder for organizations to strengthen their defenses against potential threats.

Read Original

The Pentagon has temporarily suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC), which means that third-party audits required for defense contractors will not take place for now. This suspension does not eliminate the legal requirement for companies to protect Controlled Unclassified Information (CUI). Industry experts have expressed their concern that while the audits are paused, the obligation to secure sensitive information remains critical. This situation affects defense contractors and their ability to demonstrate compliance with cybersecurity standards, potentially impacting their contracts and operations. With the growing emphasis on cybersecurity in defense, the continued protection of CUI is essential for national security.

Read Original

The article discusses the release of declassified documents related to the integrity of U.S. elections, which cybersecurity professionals are encouraged to review. These documents shed light on various aspects of election security, particularly in the context of hacking concerns that have been prevalent over the last decade. Researchers at DEF CON have been instrumental in examining vulnerabilities in voting systems, and the declassified records provide crucial insights into how past elections could have been compromised. Understanding these details is vital for improving future election security and ensuring public confidence in the electoral process. The implications of these findings extend beyond cybersecurity professionals, as they affect the integrity of democratic processes in the U.S.

Read Original
Actively Exploited

Apple has issued a warning to iPhone and iPad users about a new scam that utilizes FaceTime calls to deceive people into giving away their financial information. Scammers impersonate trusted organizations, such as banks or Apple itself, using a technique called caller ID spoofing, which makes the call appear to come from a legitimate source. This manipulation aims to extract sensitive details like account credentials and security codes. Users need to be vigilant and verify any unexpected calls requesting personal information, as this scam can lead to significant financial loss. This situation is particularly concerning as it exploits a widely used communication tool, making it crucial for users to remain cautious and informed.

Read Original

Researchers at Cisco Talos have identified a new campaign by a Russian-speaking group known as UAT-11795, which is distributing fake installers for popular applications like Zoom, Webex, and MobaXterm. These malicious installers are designed to deliver the Starland Remote Access Trojan (RAT) and a memory-only implant called WLDR. The campaign has been targeting users primarily in the United States and Europe. This is concerning as it highlights the ongoing threat posed by financially motivated cybercriminals who exploit trusted software to gain access to sensitive systems. Users should be wary of downloading software from unofficial sources and ensure they are using legitimate installation files to protect against such attacks.

Read Original

Nichirei, a major Japanese frozen food company, faced a cyberattack on July 13, which forced the company to disconnect its systems. As a result, operations were significantly disrupted, impacting their ability to process and distribute their products. The company is now in the process of gradually restoring its systems, but the incident raises concerns about the security of supply chains in the food industry. Cyberattacks on food companies can disrupt not only business operations but also affect food availability and consumer trust. Nichirei's experience serves as a reminder for companies in all sectors to prioritize cybersecurity to protect against similar threats.

Read Original
Actively Exploited

Recent analysis by ReliaQuest shows that a ransomware group known as The Gentlemen has now surpassed Qilin in the frequency of attacks. This shift indicates a changing dynamic in the ransomware world, where The Gentlemen is increasingly targeting organizations across various sectors. The report suggests that companies need to be vigilant as this group is known for its aggressive tactics and ability to exploit vulnerabilities quickly. The rise of The Gentlemen highlights the ongoing challenges businesses face in defending against ransomware threats, which can lead to significant financial losses and data breaches. Organizations are urged to enhance their cybersecurity measures to mitigate the risks posed by these evolving threats.

Read Original

Researchers have identified a new malware strain named GoSerpent, which has been targeting government and diplomatic entities in Southeast Asia since late 2025. Discovered by Kaspersky in February 2026, GoSerpent is designed for long-term access and intelligence gathering, indicating a sophisticated level of espionage. The malware's specific targets include various Southeast Asian governments and their associated diplomatic missions, raising concerns about national security and the potential for sensitive information to be compromised. The emergence of GoSerpent highlights the ongoing cyber threats faced by government institutions in the region, emphasizing the need for enhanced cybersecurity measures. As attacks like these become more common, governments must prioritize their defenses against such persistent threats.

Read Original
PreviousPage 97 of 369Next